Kaseya Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Kaseya products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
4
In CISA KEV
2
Beyond CISA KEV
2
Sensor Observed
0
Virtual Patch Available
0
Kaseya KEVs Added by Year
4 Kaseya KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2021-30118
Unauthenticated Remote Code Execution in Kaseya VSA < v9.5.5 |
VSA | High | Not in CISA | 18 Dec 2025 |
|
CVE-2021-30116
Unauthenticated credential leak and business logic flaw in Kaseya VSA <= v9.5.6 |
VSA | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2018-20753
Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell... |
VSA RMM | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-2863
Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 before 9.0.0.14, and 9.1... |
Virtual System Administrator (VSA) | High | Not in CISA | 20 Jul 2015 |
Common Vulnerability Classes (CWE)
- CWE-434 — Unrestricted Upload of File with Dangerous Type 1
- CWE-522 — Insufficiently Protected Credentials 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology